VendorsOISFsuricataall versions
Vulnerabilities

OISF Suricata

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

74CVEs
CVE-2026-45770
Suricata lua: excessive flow variable registration can bypass sandbox
Published 2026-09-10 · Analyzed
7.5EPSS 0.005
CVE-2025-53538
Suricata's mishandling of data on HTTP2 stream 0 can lead to resource starvation
Published 2025-07-22 · Analyzed
7.5EPSS 0.005
CVE-2026-31937
Suricata dcerpc: quadratic complexity in dcerpc buffering
Published 2026-04-02 · Analyzed
7.5EPSS 0.005
CVE-2026-31935
Suricata http2: unbounded resource consumption
Published 2026-04-02 · Analyzed
7.5EPSS 0.005
CVE-2026-31934
Suricata smtp/mine: quadratic complexity in extracting urls
Published 2026-04-02 · Analyzed
7.5EPSS 0.005
CVE-2026-31933
Suricata stream: quadratic complexity in stream inspection
Published 2026-04-02 · Analyzed
7.5EPSS 0.005
CVE-2026-31932
Suricata krb5: quadratic complexity in krb5 buffering
Published 2026-04-02 · Analyzed
7.5EPSS 0.005
CVE-2026-31931
Suricata tls: null dereference in tls.alpn rule keyword
Published 2026-04-02 · Analyzed
7.5EPSS 0.005
CVE-2025-59148
Suricata's improper use of entropy keyword can lead to a NULL-ptr deref
Published 2025-10-01 · Analyzed
7.5EPSS 0.004
CVE-2025-64335
Suricata is vulnerable to a null deref when used with base64_data
Published 2025-11-26 · Modified
7.5EPSS 0.004
CVE-2025-59147
Suricata is Vulnerable to Detection Bypass via Crafted Multiple SYN Packets
Published 2025-10-01 · Analyzed
7.5EPSS 0.004
CVE-2025-64330
Suricata is vulnerable to a heap buffer overflow on verdict
Published 2025-11-26 · Analyzed
7.5EPSS 0.004
CVE-2025-64332
Suricata is vulnerable to a stack overflow on larger compressed data
Published 2025-11-26 · Analyzed
7.5EPSS 0.004
CVE-2025-64334
Suricata is vulnerable to unbounded memory growth for decompression
Published 2025-11-26 · Analyzed
7.5EPSS 0.004
CVE-2025-64344
Suricata is vulnerable to a stack overflow from unbounded stack allocation in LuaPushStringBuffer
Published 2025-11-26 · Analyzed
7.5EPSS 0.004
CVE-2025-64331
Suricata is vulnerable to a stack overflow on large file transfers with http-body-printable
Published 2025-11-26 · Analyzed
7.5EPSS 0.003
CVE-2025-64333
Suricata is vulnerable to a stack overflow from big content-type
Published 2025-11-26 · Analyzed
7.5EPSS 0.003
CVE-2024-47187
Suricata datasets: missing hashtable random seed leads to potential DoS
Published 2024-10-16 · Analyzed
7.5EPSS 0.003
CVE-2024-47188
Suricata http/byte-ranges: missing hashtable random seed leads to potential DoS
Published 2024-10-16 · Analyzed
7.5EPSS 0.003
CVE-2025-29915
Suricata af-packet: defrag option can lead to truncated packets affecting visibility
Published 2025-04-10 · Analyzed
7.5EPSS 0.003
CVE-2024-32664
Suricata's base64 contains an out of bounds write
Published 2024-05-07 · Analyzed
7.3EPSS 0.009
CVE-2025-29918
Suricata pcre: negated pcr can cause infinite loop
Published 2025-04-10 · Modified
6.2EPSS 0.003
CVE-2025-29917
Suricata decode_base64: signature can do large memory allocation
Published 2025-04-10 · Analyzed
6.2EPSS 0.003
CVE-2025-29916
Suricata datasets: ruleset declared settings can lead to resource starvation
Published 2025-04-10 · Analyzed
6.2EPSS 0.003
CVE-2025-59149
Suricata: Stack buffer overflow in rule parser when processing long keywords with transforms
Published 2025-10-01 · Analyzed
6.2EPSS 0.002
CVE-2024-55626
Suricata oversized bpf file can lead to buffer overflow
Published 2025-01-06 · Modified
5.5EPSS 0.002
CVE-2024-32867
Suricata's defrag contains various issues leading to policy bypass
Published 2024-05-07 · Analyzed
5.3EPSS 0.007
CVE-2024-24568
Suricata http2: header handling evasion
Published 2024-02-26 · Analyzed
5.3EPSS 0.006
CVE-2024-45796
Suricata defrag: off by one can lead to policy bypass
Published 2024-10-16 · Modified
5.3EPSS 0.005
CVE-2026-22263
Suricata http1: quadratic complexity in headers parsing over multiple packets
Published 2026-01-27 · Analyzed
5.3EPSS 0.005
CVE-2026-22261
Suricata eve/alert: http1 xff handling can lead to denial of service
Published 2026-01-27 · Analyzed
5.3EPSS 0.004
CVE-2013-5919
Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
Published 2014-05-30 · Modified
5.0EPSS 0.016
CVE-2026-45767
Suricata datasets: save to absolute filename can be bypassed when combined with load command
Published 2026-09-10 · Analyzed
4.4EPSS 0.004
CVE-2026-45761
Suricata detect: case-insensitive frame handling can cause heap buffer overflow during rule load
Published 2026-09-10 · Analyzed
3.3EPSS 0.002
← Prev2 / 2